Impact
HCL BigFix Service Management (SM) suffers from insufficiently protected credentials while it communicates with a backend internal application. The flaw, classified as CWE-200, allows an attacker who can observe or intercept this short‑lived transmission to capture the credentials and potentially misuse them for unauthorized access. The vulnerability does not grant immediate remote code execution or denial of service; its primary danger is credential compromise and the downstream attacks it enables.
Affected Systems
The affected product is HCL Software’s BigFix Service Management (SM). No specific version numbers are listed in the data, so all current installations are considered potentially vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 4.8 indicates moderate severity, while the EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is network interception between SM and its backend during the brief credential transmission period; an attacker would need network access that allows sniffing or man‑in‑the‑middle. Because the credentials are only briefly exposed, the opportunity window is narrow, but the impact of any exfiltrated credentials could be significant if used to gain further access.
OpenCVE Enrichment